Critical

Siemens Desigo DXR and PXC Controllers

All CISA Advisories

Overview

Siemens has identified a vulnerability affecting its Desigo DXR and PXC controllers that could enable attackers to initiate denial of service (DoS) conditions by sending malformed BACnet packets. This issue can cause the devices to stop responding to BACnet queries, requiring a reset or reboot for recovery. The affected versions include Desigo DXR2, PXC3, PXC4, PXC5.E003, PXC5.E24, and PXC7, all of which are used across various sectors such as healthcare, energy, and transportation. Siemens has released updated versions to address this vulnerability and strongly urges users to apply these updates to maintain device functionality and security.

Key Takeaways

  • Affected Systems: Affected products include Siemens Desigo DXR2 (versions < V01.21.233.16-7862), PXC3 (versions < V01.21.233.16-7862), PXC4 (versions < V02.21.194.36-2715), PXC5.E003 (versions < V02.21.194.36-2715), PXC5.E24 (versions < V02.21.194.36-2715), and PXC7 (versions < V02.21.194.36-2715).
  • Action Required: Users should update to Desigo DXR2 version V01.
  • Timeline: Disclosed on August 11, 2026

Original Article Summary

View CSAF Summary A vulnerability in Desigo DXR and PXC controllers has been identified that could allow an attacker to cause denial of service conditions by sending malformed BACnet packets. Recovery requires a device reset or reboot to restore normal functionality. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Desigo DXR and PXC Controllers are affected: Desigo DXR2 vers:intdot/<01.21.233.16-7862 (CVE-2026-59693) Desigo PXC3 vers:intdot/<01.21.233.16-7862 (CVE-2026-59693) Desigo PXC4 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693) Desigo PXC5.E003 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693) Desigo PXC5.E24 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693) Desigo PXC7 vers:intdot/<02.21.194.36-2715 (CVE-2026-59693) CVSS Vendor Equipment Vulnerabilities v3 4.3 Siemens Siemens Desigo DXR and PXC Controllers Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Commercial Facilities, Critical Manufacturing, Energy, Healthcare and Public Health, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-59693 The affected devices are vulnerable to a denial-of-service (DoS) vulnerability. An attacker can exploit this issue by sending a malformed BACnet packet, causing the device to stop responding to BACnet queries. Recovery requires a device reset or reboot to restore normal functionality. View CVE Details Affected Products Siemens Desigo DXR and PXC Controllers Vendor: Siemens Product Version: Desigo DXR2 < V01.21.233.16-7862, Desigo PXC3 < V01.21.233.16-7862, Desigo PXC4 < V02.21.194.36-2715, Desigo PXC5.E003 < V02.21.194.36-2715, Desigo PXC5.E24 < V02.21.194.36-2715, Desigo PXC7 < V02.21.194.36-2715 Product Status: known_affected Remediations Vendor fix Update to V01.21.233.16-7862 or later version Please contact your local Siemens office for additional support in obtaining the update. Vendor fix Update to V02.21.194.36-2715 or later version Please contact your local Siemens office for additional support in obtaining the update. Relevant CWE: CWE-754 Improper Check for Unusual or Exceptional Conditions Metrics CVSS Version Base Score Base Severity Vector String 3.1 4.3 MEDIUM CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Acknowledgments Thomas EBI of Sauter reported this vulnerability to Siemens General Recommendations As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial-security), and following the recommendations in the product manuals. Additional information on Industrial Security by Siemens can be found at: https://www.siemens.com/industrialsecurity Additional Resources For further inquiries on security vulnerabilities in Siemens products and solutions, please contact the Siemens ProductCERT: https://www.siemens.com/cert/advisories Terms of Use The use of Siemens Security Advisories is subject to the terms and conditions listed on: https://www.siemens.com/productcert/terms-of-use. Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as virtual private networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available. Also recognize VPN is only as secure as its connected devices. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures. CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies. CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets. Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov in the technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies. Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents. Advisory Conversion Disclaimer This ICSA is a verbatim republication of Siemens SSA-781903 from a direct conversion of the vendor's Common Security Advisory Framework (CSAF) advisory. This is republished to CISA's website as a means of increasing visibility and is provided "as-is" for informational purposes only. CISA is not responsible for the editorial or technical accuracy of republished advisories and provides no warranties of any kind regarding any information contained within this advisory. Further, CISA does not endorse any commercial product or service. Please contact Siemens ProductCERT directly for any questions regarding this advisory. Revision History Initial Release Date: 2026-08-11 Date Revision Summary 2026-08-11 1 Publication Date 2026-08-13 2 Initial CISA Republication of Siemens SSA-781903 advisory Legal Notice and Terms of Use

Impact

Affected products include Siemens Desigo DXR2 (versions < V01.21.233.16-7862), PXC3 (versions < V01.21.233.16-7862), PXC4 (versions < V02.21.194.36-2715), PXC5.E003 (versions < V02.21.194.36-2715), PXC5.E24 (versions < V02.21.194.36-2715), and PXC7 (versions < V02.21.194.36-2715).

Exploitation Status

No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.

Timeline

Disclosed on August 11, 2026

Remediation

Users should update to Desigo DXR2 version V01.21.233.16-7862 or later, and for PXC controllers, update to version V02.21.194.36-2715 or later. For assistance, users are advised to contact their local Siemens office.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 2 more.

Related Coverage

Interpol targets Black Axe’s illicit financial web in latest international sting

CyberScoop

Interpol has launched a major international operation targeting the financial networks of the Black Axe criminal organization, which is involved in various illicit activities across multiple continents. This coordinated sting involved several countries and resulted in the seizure of millions of dollars in assets. Authorities also uncovered infrastructure that supports 'Crime-as-a-Service', indicating a sophisticated level of organization within Black Axe. This operation not only disrupts their financial operations but also highlights the ongoing global efforts to combat cybercrime. The implications of this sting are significant as it aims to dismantle a key player in the world of cybercrime, potentially reducing the threats posed to individuals and businesses worldwide.

Aug 25, 2026

From Fake Workers to Account Recovery: The Growing Identity Verification Risk

BleepingComputer

Attackers are shifting their focus from directly compromising login credentials to exploiting identity verification processes. This change in tactics poses significant risks, allowing bad actors to create fake identities or manipulate recovery procedures to gain unauthorized access. Organizations that rely on weak verification methods are particularly vulnerable to social engineering attacks, which can lead to data breaches and loss of sensitive information. Strengthening identity verification processes is essential to mitigate these risks and protect both employees and customers. Companies must adopt more robust methods to ensure that only legitimate users can access their systems, thereby reducing the chances of fraudulent activities.

Aug 25, 2026

INTERPOL crackdown on West African crime rings uncovers troubling new trend

Help Net Security

INTERPOL recently conducted an extensive operation called Jackal IV, targeting organized crime groups in West Africa. Over eight months, police in 22 countries arrested 58 individuals and identified 263 suspects linked to groups like Black Axe, known for their involvement in money laundering and other illicit activities. The operation aimed to disrupt these crime networks by seizing assets and facilitating arrests. This crackdown reveals a troubling trend of increasing organized crime activity in the region, which poses significant challenges for law enforcement and raises concerns about the broader impact on security and governance in West Africa. The collaboration across multiple countries underscores the need for a united front against such transnational crime.

Aug 25, 2026

WhatsApp adds stronger two-step verification, multiple passkeys

BleepingComputer

WhatsApp is enhancing its account security with the introduction of multiple passkeys and a more robust two-step verification process. These features aim to provide users with better protection against unauthorized access to their accounts. The update is part of WhatsApp's ongoing efforts to improve security, especially as the platform continues to grow in popularity. Users will benefit from these added layers of security, making it harder for attackers to compromise their accounts. This move is particularly important given the increasing number of phishing attempts and account takeovers targeting messaging apps.

Aug 25, 2026

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

The Hacker News

Marimo has fixed a serious security flaw in its notebook software that could allow attackers to run unauthorized commands. This vulnerability, identified by VulnCheck's CVE Numbering Authority, enables an attacker to execute Model Context Protocol (MCP) commands when a specially crafted notebook is opened in edit mode. If exploited, this could lead to unauthorized actions on a user's system, particularly affecting individuals using the notebook software in environments where sensitive data is handled. Users are urged to update their software promptly to mitigate potential risks associated with this flaw.

Aug 25, 2026

Check Point Threat Brief: Critical Infrastructure Breaches and Emerging AI Attack Surfaces

Cyber Defense Magazine

Check Point Research recently reported on a series of significant security breaches affecting critical infrastructure and the emergence of new AI-related attack methods. These breaches pose serious risks to various sectors, highlighting vulnerabilities that attackers may exploit. The report, released on August 24, emphasizes the need for organizations to bolster their defenses against these evolving threats. As cybercriminals continue to adapt their strategies, it is crucial for companies to stay informed and proactive in their cybersecurity measures. This situation underscores the importance of vigilance in protecting sensitive systems and data from increasingly sophisticated attacks.

Aug 25, 2026